ABXZone Computer  Forums



Welcome to the ABXZone Computer Forums forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Reply
 
LinkBack Thread Tools Display Modes
Old 02-02-2005, 02:17 PM   #241
.
 
Join Date: Feb 2001
Posts: 2,669

Nice find! Please submit this to the news section so I can validate it.

__________________
My Blog
(Offline)   Reply With Quote
Old 02-02-2005, 02:25 PM   #242
Level 15, lawful good
 
Cogar's Avatar
 
Join Date: Dec 2002
Location: It varies, but usually within 100 yards of a keyboard.
Posts: 7,222
Quote:
Originally Posted by TweakHound
Nice find! Please submit this to the news section so I can validate it.
You got it!
(Offline)   Reply With Quote
Old 02-02-2005, 02:33 PM   #243
Registered User
 
Join Date: Oct 2003
Posts: 394
hmm...if anyone is looking for a good wireless-g router with SPI etc check out the Linksys WRT54GS ( $69 after mail-ins)

http://www.newegg.com/app/ViewProduc...124-136&depa=0


Its been pretty good so far but I've only had it for 2 weeks now..

(Offline)   Reply With Quote
Old 02-02-2005, 03:01 PM   #244
The Shade of Lazarus
 
KingTermite's Avatar
 
Join Date: Jun 2002
Location: PM me to keep in contact
Posts: 26,003
Scott Culp's 10 Immutable Laws of Security

How to think like a hacker - Scott Culp's 10 Immutable Laws of Security

Back in the year 2000 Scott Culp published a paper outlining the 10 Immutable Laws of Security. I've restated them here to be concise but strongly encourage you to read the original article as it develops each law to discuss each in turn.

If you're new to information security and would like to put everything in context then Scott's paper will help. In addition remember that information security is all about risk measurement, mitigation together with policy, process and people - security policy must support the requirements of the business whilst mitigating the risks to a level that the company are comfortable with.

Policy and processes must be constantly reviewed and updated to ensure compliance with the requirements and operation of the business. People outside the security team must be involved with and buy into the security of information otherwise they are likely to take shortcuts.

Security Policy must be realistic - users can be encouraged to comply with reasonable security policy and associated guidelines - if they think "the policy's stupid" then they are far less likely to follow it. Security policies must "have teeth" to make it clear to users that failure to comply will result in consequences.

Here are the 10 Immutable Laws of Security:

Law #1: If a bad guy can persuade you to run his program on your computer, it's not your computer anymore



Law #2: If a bad guy can alter the operating system on your computer, it's not your computer anymore



Law #3: If a bad guy has unrestricted physical access to your computer, it's not your computer anymore



Law #4: If you allow a bad guy to upload programs to your website, it's not your website any more



Law #5: Weak passwords trump strong security



Law #6: A computer is only as secure as the administrator is trustworthy



Law #7: Encrypted data is only as secure as the decryption key



Law #8: An out of date virus scanner is only marginally better than no virus scanner at all



Law #9: Absolute anonymity isn't practical, in real life or on the Web



Law #10: Technology is not a panacea





Taken from < here > !
__________________

Bye Bye ABXZone.....Rest In Peace.
(Offline)   Reply With Quote
Old 02-02-2005, 03:02 PM   #245
Registered User
 
Join Date: Nov 2003
Posts: 13,497
FYI, a lot of the info in this thread has been update, corrected, consolidated and expanded. It all appears in the Securing Windows XP paper that Tweakhound and I co-authored. You can find that in the Reviews Forum. It might be easier for you then going through this long thread, although there is more product specific info here than in the paper.
(Offline)   Reply With Quote
Old 02-02-2005, 03:16 PM   #246
Level 15, lawful good
 
Cogar's Avatar
 
Join Date: Dec 2002
Location: It varies, but usually within 100 yards of a keyboard.
Posts: 7,222
That is a great article KT. It is even simple enough that I can understand it.
(Offline)   Reply With Quote
Old 02-02-2005, 03:22 PM   #247
Registered User
 
Join Date: Nov 2003
Posts: 13,497
To make this thread easier to find, I have restuck it for the time being. I had unstuck it after Tweakhound and I posted our paper because that is more definitive on the subject then this thread.
(Offline)   Reply With Quote
Old 02-02-2005, 03:22 PM   #248
The race for quality has no finish line- so technically, it's more like a death march.
 
Join Date: Feb 2001
Posts: 18,159
Great article and this could very well be my next career move. However, I already think like a hacker, it's thinking like a cracker that is important to me.

Thanks for finding this article.
__________________

(Offline)   Reply With Quote
Old 02-02-2005, 04:08 PM   #249
Never Ending
 
wayne_abx's Avatar
 
Join Date: Jul 2002
Location: Vancouver, Washington (State)
Posts: 4,188
Quote:
Originally Posted by giga_dude
hmm...if anyone is looking for a good wireless-g router with SPI etc check out the Linksys WRT54GS ( $69 after mail-ins)

http://www.newegg.com/app/ViewProduc...124-136&depa=0


Its been pretty good so far but I've only had it for 2 weeks now..

Yap, It is what I use w/WPA and OSS firmware thus I use third party firmware Up Time: 100 days, 20:22:18 since my last boot and that was because of a firmware upgrade.

-wayne
__________________
System-1 (primary)
Intel D875PBZLK FMB 1.5 > Pentium 4/ 3.0E (D0) > Crucial Ballistix 512mb PC4000 (Dual Channel) > ATI Radeon 9500 Pro (128) > Audigy 2 Platinum > Thermaltake P4 Spark 7+ (Xaser Edition) - Antec 80x80mm x5 > 1x 80GB WD SE - 2x Seagate 200GB 7200RPM Barracuda 7200.7 Plus SATA > Lite-On LDW811s dvd +/- Tashiba SDM1712 DvD > Antec 430 TP > WinXP W/SP-2

Gigabit Network, Linksys WRT54GS, Linksys EG008W 8-port gigabit switch, ximeta network storage, Motorola SB4200
(Offline)   Reply With Quote
Old 02-02-2005, 06:29 PM   #250
Sumtin Stnks !
 
Shadow_419's Avatar
 
Join Date: Sep 2003
Location: South Coast Mass
Posts: 1,270
I've just succesfully stealthed my router
It took a little while to figure out how to stealth port 113 but the tips at shields up and this thread were great. Thanks again to PCB, Tweakhound, and all the other members who left thier input
__________________
DFI NF4 Ultra-D Opty 165 @ 2.95 Ghz : Scythe Mine w/ 120mm Yate Loon
2 x 1GB G.Skill DDR500 : Evga 7900GS
WD 250 GB sata : Lite-On Dvd-Rw sata
Enermax Liberty
(Offline)   Reply With Quote
Old 02-03-2005, 01:41 PM   #251
Registered User
 
Join Date: Oct 2003
Posts: 394
Quote:
Originally Posted by wayne
Yap, It is what I use w/WPA and OSS firmware thus I use third party firmware Up Time: 100 days, 20:22:18 since my last boot and that was because of a firmware upgrade.

-wayne
What firmware do you use? The Sveasoft one or?

(Offline)   Reply With Quote
Old 02-03-2005, 02:22 PM   #252
Never Ending
 
wayne_abx's Avatar
 
Join Date: Jul 2002
Location: Vancouver, Washington (State)
Posts: 4,188
Quote:
Originally Posted by giga_dude
What firmware do you use? The Sveasoft one or?

I have used Sveasoft, currenty using HyperWRT Sveasoft "Alchemy" is still in beta though there is others out there such as DD-WRt

I like both Sveasoft and HyperWRT they both bring different venues to the table though Sveasoft charges $20usd

-wayne
__________________
System-1 (primary)
Intel D875PBZLK FMB 1.5 > Pentium 4/ 3.0E (D0) > Crucial Ballistix 512mb PC4000 (Dual Channel) > ATI Radeon 9500 Pro (128) > Audigy 2 Platinum > Thermaltake P4 Spark 7+ (Xaser Edition) - Antec 80x80mm x5 > 1x 80GB WD SE - 2x Seagate 200GB 7200RPM Barracuda 7200.7 Plus SATA > Lite-On LDW811s dvd +/- Tashiba SDM1712 DvD > Antec 430 TP > WinXP W/SP-2

Gigabit Network, Linksys WRT54GS, Linksys EG008W 8-port gigabit switch, ximeta network storage, Motorola SB4200
(Offline)   Reply With Quote
Old 02-03-2005, 03:17 PM   #253
Registered User
 
Join Date: Oct 2003
Posts: 394
do you have a linkie by any chance?

This is the one that I found: http://www.hyperdrive.be/hyperwrt/

(Offline)   Reply With Quote
Old 02-03-2005, 03:42 PM   #254
Never Ending
 
wayne_abx's Avatar
 
Join Date: Jul 2002
Location: Vancouver, Washington (State)
Posts: 4,188
DD-WRt

Alchemy is still beta and not released yet, DD-WRt is bassed on Alchemy

WARNING:
if you don't need the extra features and have no issue with linksys supplied Firmware, then I see no need to use a third party firmware since it is NOT supported by Linksys, if you choose to go ahead and use a third party firmware then be sure to back up the good working firmware that is already in the router by using the router's built-in backup feature.
CAUTION:
DON"T flash the routers firmware by wireless means!

-wayne
__________________
System-1 (primary)
Intel D875PBZLK FMB 1.5 > Pentium 4/ 3.0E (D0) > Crucial Ballistix 512mb PC4000 (Dual Channel) > ATI Radeon 9500 Pro (128) > Audigy 2 Platinum > Thermaltake P4 Spark 7+ (Xaser Edition) - Antec 80x80mm x5 > 1x 80GB WD SE - 2x Seagate 200GB 7200RPM Barracuda 7200.7 Plus SATA > Lite-On LDW811s dvd +/- Tashiba SDM1712 DvD > Antec 430 TP > WinXP W/SP-2

Gigabit Network, Linksys WRT54GS, Linksys EG008W 8-port gigabit switch, ximeta network storage, Motorola SB4200
(Offline)   Reply With Quote
Old 02-03-2005, 04:24 PM   #255
Registered User
 
Join Date: Oct 2003
Posts: 394
Quote:
Originally Posted by wayne
DD-WRt

Alchemy is still beta and not released yet, DD-WRt is bassed on Alchemy

WARNING:
if you don't need the extra features and have no issue with linksys supplied Firmware, then I see no need to use a third party firmware since it is NOT supported by Linksys, if you choose to go ahead and use a third party firmware then be sure to back up the good working firmware that is already in the router by using the router's built-in backup feature.
CAUTION:
DON"T flash the routers firmware by wireless means!

-wayne

No problem wayne. I'm merely looking into the bonus features that could be gained by using 3rd party firmware. The only issues I have right now is speed....so Im just looking to see if I can upgrade the firmware & achieve moderate gains....

(Offline)   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Powered by vBulletin® Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.1
vBulletin Skin developed by: vBStyles.com